S4E just found a low-severity finding from [ai] web application external link detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jul 2, 2024

CVE-2024-26331 Scanner

CVE-2024-26331 scanner - Unauthorized Admin Access vulnerability in ReCrystallize Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-26331
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to a session ID. Attackers can easily modify the cookie value, within a browser or by implementing client-side code outside of a browser. Attackers can bypass the authentication mechanism by modifying the cookie to contain an expected value.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
recrystallize_serverby recrystallize_software
5.10.0.0
Updated Aug 22, 2026View on NVD →
Detail

ReCrystallize Server is used for managing and distributing Crystal Reports on a network. It is commonly deployed by organizations needing robust reporting capabilities. IT administrators and developers use it to ensure reports are available to end-users. The software integrates with various data sources, providing dynamic report generation. Its web-based interface facilitates easy access and management of reports.

This vulnerability allows an attacker to bypass authentication by manipulating the 'AdminUsername' cookie. By setting this cookie, an attacker can gain administrative access to the application. This grants full control over the system, including the ability to modify configurations and access sensitive information. The vulnerability exists even if the default password is changed.

The vulnerability is found in the ReCrystallize Server's handling of the 'AdminUsername' cookie. An attacker can set this cookie to 'admin' and send a GET request to '/Admin/Admin.aspx'. The server fails to validate the authentication token properly, allowing access to the administrative interface. The presence of specific keywords like "ReCrystallize Server Administration" confirms the exploit. This endpoint is crucial for administrative functions, making it a significant security risk.

Exploiting this vulnerability allows attackers to take full control of the ReCrystallize Server. They can access and modify sensitive configurations and data. Unauthorized administrative access can lead to data breaches, service disruptions, and potential loss of data integrity. Malicious actors can also leverage this access to launch further attacks on the network.

Join the S4E platform to secure your digital assets with our comprehensive vulnerability scanning service. Our platform offers detailed reports and remediation steps to protect your systems from threats like unauthorized admin access. Benefit from continuous monitoring and expert guidance to maintain robust security posture. Sign up today to safeguard your infrastructure against emerging vulnerabilities.

References:

Solution Advice
  • Implement proper validation for all cookies, especially those used for authentication.
  • Use secure authentication mechanisms that do not rely solely on cookies.
  • Regularly update and patch your software to mitigate known vulnerabilities.
  • Monitor and audit access logs for suspicious activities.
  • Enforce strong administrative controls and policies.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.